Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

README.md

THOR Object Type Reference

Source: THOR --describe-object-type all (89 object types)

This reference maps every THOR object type to its available fields, types, and required status. Use it when writing custom Sigma rules with product: THOR.

Field naming convention:

  • In THOR JSON output: lowercase with underscores (e.g., run_as_user, image.path)
  • In Sigma rules: UPPERCASE top-level field only (e.g., RUN_AS_USER, COMMAND)
  • Object null-check syntax exists but was observed matching all objects in THOR v11.0.0 — verify before relying on it

⚠️ Nested sub-fields (e.g., image.path, hashes.md5) are NOT directly referenceable in Sigma rules. THOR's Sigma backend matches on top-level fields only. The tables in each object type doc show the JSON structure for reference, but you cannot write IMAGE.PATH or IMAGE_PATH in a Sigma rule.

Standard Sigma field mappings (from tmpl-sigma.yml):

  • CommandLinecommand | ProcessIdpid | Imageimage (object)
  • ParentImageparent_info (object) | Userowner | TargetFilenamepath

Platform

Object Type Fields Sigma Service
AIX platform information 9 product: THOR, service: "AIX platform information"
Linux platform information 6 product: THOR, service: "Linux platform information"
MacOS platform information 7 product: THOR, service: "MacOS platform information"
Windows platform information 8 product: THOR, service: "Windows platform information"

Execution History

Object Type Fields Sigma Service
AmCache entry 9 product: THOR, service: "AmCache entry"
web download 4 product: THOR, service: "web download"
web page visit 4 product: THOR, service: "web page visit"

Network

Object Type Fields Sigma Service
DNS cache entry 3 product: THOR, service: "DNS cache entry"
MS Office connection cache entry 4 product: THOR, service: "MS Office connection cache entry"
firewall rule 11 product: THOR, service: "firewall rule"
network session 7 product: THOR, service: "network session"
network share 4 product: THOR, service: "network share"
raw firewall rule 2 product: THOR, service: "raw firewall rule"

Logs & Events

Object Type Fields Sigma Service
DetectionAdd MPLog entry 4 product: THOR, service: "DetectionAdd MPLog entry"
EMS detection MPLog entry 4 product: THOR, service: "EMS detection MPLog entry"
EstimatedImpact MPLog entry 5 product: THOR, service: "EstimatedImpact MPLog entry"
SDN query MPLog entry 5 product: THOR, service: "SDN query MPLog entry"
audit log entry 2 product: THOR, service: "audit log entry"
eventlog entry 2 product: THOR, service: "eventlog entry"
journal log entry 3 product: THOR, service: "journal log entry"
log line 3 product: THOR, service: "log line"

Identity & Auth

Object Type Fields Sigma Service
DoublePulsar Handshake 3 product: THOR, service: "DoublePulsar Handshake"
LSA session 8 product: THOR, service: "LSA session"
Tomcat user 2 product: THOR, service: "Tomcat user"
Unix user 9 product: THOR, service: "Unix user"
User Access Log Entry 12 product: THOR, service: "User Access Log Entry"
Windows user 12 product: THOR, service: "Windows user"
authorized_keys entry 5 product: THOR, service: "authorized_keys entry"
groups.xml user 3 product: THOR, service: "groups.xml user"
logged in user 5 product: THOR, service: "logged in user"

Other

Object Type Fields Sigma Service
KnowledgeDB entry 6 product: THOR, service: "KnowledgeDB entry"
PowerShell module analysis cache module entry 3 product: THOR, service: "PowerShell module analysis cache module entry"
SRUM Resource Usage Entry 14 product: THOR, service: "SRUM Resource Usage Entry"
THOR assessment 10 product: THOR, service: "THOR assessment"
THOR invocation information 17 product: THOR, service: "THOR invocation information"
THOR message 5 product: THOR, service: "THOR message"
TeamViewer password 3 product: THOR, service: "TeamViewer password"
TestObject 7 product: THOR, service: "TestObject"
USN entry 4 product: THOR, service: "USN entry"
Unix permissions 4 product: THOR, service: "Unix permissions"
Windows permissions 3 product: THOR, service: "Windows permissions"
eBPF program 13 product: THOR, service: "eBPF program"
end of life report 3 product: THOR, service: "end of life report"
environment variable 3 product: THOR, service: "environment variable"
event 2 product: THOR, service: "event"
hotfix summary 2 product: THOR, service: "hotfix summary"
multiChoiceA 2 product: THOR, service: "multiChoiceA"
quarantine event 6 product: THOR, service: "quarantine event"
reason 4 product: THOR, service: "reason"
registered debugger 3 product: THOR, service: "registered debugger"
rootkit 1 product: THOR, service: "rootkit"
shellbag entry 4 product: THOR, service: "shellbag entry"
sparse data 3 product: THOR, service: "sparse data"
structured data from plugin 3 product: THOR, service: "structured data from plugin"
system information 12 product: THOR, service: "system information"

Persistence & System

Object Type Fields Sigma Service
Linux kernel module 15 product: THOR, service: "Linux kernel module"
WMI element 7 product: THOR, service: "WMI element"
WMI startup command 4 product: THOR, service: "WMI startup command"
Windows service 11 product: THOR, service: "Windows service"
at job 2 product: THOR, service: "at job"
autorun entry 8 product: THOR, service: "autorun entry"
cron job 4 product: THOR, service: "cron job"
init.d service 2 product: THOR, service: "init.d service"
registry scheduled task 9 product: THOR, service: "registry scheduled task"
scheduled task 13 product: THOR, service: "scheduled task"
systemd service 6 product: THOR, service: "systemd service"

File System

Object Type Fields Sigma Service
MFT entry 11 product: THOR, service: "MFT entry"
file 19 product: THOR, service: "file"
file chunk 5 product: THOR, service: "file chunk"
hosts file entry 3 product: THOR, service: "hosts file entry"
jump list entry 11 product: THOR, service: "jump list entry"
prefetch info 5 product: THOR, service: "prefetch info"
shim cache 3 product: THOR, service: "shim cache"
shim cache entry 4 product: THOR, service: "shim cache entry"
shim database entry 2 product: THOR, service: "shim database entry"
user profile 4 product: THOR, service: "user profile"

Security & Kernel

Object Type Fields Sigma Service
antivirus exclusion 3 product: THOR, service: "antivirus exclusion"
antivirus product 5 product: THOR, service: "antivirus product"
mutex 2 product: THOR, service: "mutex"
named pipe 2 product: THOR, service: "named pipe"
pipe list 2 product: THOR, service: "pipe list"

Process & Memory

Object Type Fields Sigma Service
network connecting thread 5 product: THOR, service: "network connecting thread"
process 16 product: THOR, service: "process"
process connection 7 product: THOR, service: "process connection"
process handle 4 product: THOR, service: "process handle"
process start 3 product: THOR, service: "process start"
thread 3 product: THOR, service: "thread"

Registry

Object Type Fields Sigma Service
registry key 4 product: THOR, service: "registry key"
registry value 5 product: THOR, service: "registry value"